VDB

JLSEC-2026-17

JLSEC-2026-17 PUBLISHED CVSS 9.300000190734863 CRITICAL

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.

Risk Scores

CVSS 2.0
9.300000190734863

Affected Products

VendorProductVersions
Juliapatch_jll0, 0
Juliapatch_jll0

Timeline

  • Mar 31, 2026 CVE Published
  • Jul 18, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›